Owner / Lead Security Consultant Resume
Ashburn, VA
OBJECTIVE
A challenging position involving the design, integration, security and operations of IT architectures and management systems.
SUMMARY
- Twenty years of leadership with service provider and enterprise management, design, operations and standardization .
- Designed and implemented security practices and achieved unprecedented accomplishments in all aspects of security and IT including radical changes to global Internet and mobile telecommunications critical infrastructures and control systems.
- Proficient in multiple programming languages, databases, operating systems, cloud platforms, hardware platforms, management systems, and security methodologies .
PROFESSIONAL EXPERIENCE
Owner / Lead Security Consultant
Confidential, Ashburn, VA
Responsibilities:
- Successfully lead ATO efforts for 32 federal agencies to certify federal PaaS HCM systems Confidential SAP, and transition to FedRAMP. Worked with SAP VP of US Ops and CISO to improve application security globally utilizing the Agile development lifecycle.
- Enhanced security practices across IT for web application vulnerabilities (WAF), phishing, DLP, forensic analysis, and malware incident response. Re - engineered and Integrated tools and procedures with security incident and event management (SIEM) systems (QRadar, Arcsight, Splunk, ISE, Radius, Active Directory, OAM) and conducted focused penetration testing for rule development and tuning. Worked with software development teams to assist with compliance, develop white-box testing, and develop threat intelligence heuristics for session authentication and authorization anomalies including xss, sql injection, and resource depletion.
- Designed a secure DevOps program for over 20 federal information systems and Agile SDLC. Worked with HRSA/FDA to remediate HP Fortify/Webinspect findings and institute procedures and controls for HIPAA compliance using the OWASP four phased maturity model and “top ten” controls. Evaluated SAST/DAST testing tools including Coverity, Seeker, Contrast Assess, AppSpider, WebInspect and others. Initiated the program strategy using iterative core processes and numerous security practice road maps. Developed cxonfidential and QA testing automation utilizing Junit, Selenium and Jenkins CI.
- Designed and Developed an AWS cloud based WAF solution based on confidential. Directed performance testing and system optimization. Designed and implemented a ZScalar cloud security solution. Designed and implemented Verisign DoS security solutions and response procedures.
- Hired, trained and developed red and blue teams, worked across organizations on a risk management and reconnaissance basis. Directed black-box testing and developed compliance dashboards, reports, and data warehousing. Directed third-party penetration testing to perform security control gap analysis.
- Participated in engineering and code review. Developed testing modules and conducted ongoing database security and cryptography control validation utilizing Perl, Java, JSON, Python, Linux, and SQL. Utilized and customized vulnerability assessment tools including, Nessus Tenable, Rapid7 Nexpose, Firemon/FMQL, Wireshark, Burpsuite, OWASP Zap, HP Webinspect/Fortify, and Qualys.
- Worked with product owners to design a cloud integrated HCM using Oracle OCI SaaS with ADP and Taleo added on. Developed vendor risk assessments and audit requirements based on SOC2 controls and business requirements. Advised senior management on C&A, SSP development, and rolling authorizations under FISMA. Advised on architectural strategy, lifecycle and security controls including IAM (Oracle OAM, Active Directory), routers/firewalls/switches (Fortigate, Juniper, ASA), IPS, WAF, IBM Guardium / Imperva SecureSphere DAM, etc.
Sr. IA Engineer
Confidential, Herndon, VA
Responsibilities:
- Worked with vendors including Oracle Corporation, VMware, Enterprise DB, and SAP to interpret national security policy for the establishment of new DIACAP assessment standards, and procedures.
- Adjudicated audit findings with software developers and operational support providing database subject matter expertise. Modified and maintained published DoD database standards accordingly.
- Designed the security architecture for encryption of data Confidential rest and in transit Confidential the White House Communications Agency .
Sr. Security Architect
Confidential, Oakton, VA
Responsibilities:
- Designed a Sourcefire IPS and SIEM solution to integrate with existing managed Enterasys and Cisco platforms. Developed capacity management and intrusion policy processes using NetScout, Defense Center, EMS, syslog and ArcSight to analyze and maintain streamlined managed security service with the global customer support organization.
- Directed CSO lab testing, analysis and certification. Coordinated and lead actual maintenance activities. Participated in regular engineering review and change control while managing vulnerabilities, service implementation, and data center consolidation. Provided tier V support for Cisco ASA, Sourcefire, Enterasys Dragon, McAfee IPS, and BlueCoat Proxy platforms.
- Developed configuration and vulnerability/patch remediation assessment software for network hardware and software in use on the federal court systems and network. Audited the network, developed and maintained system security plans based on NIST 800-53, ITILv3, SAS70, and DIACAP. Planned and remediated vulnerabilities.
- Directed external penetration testing and defined remediation requirements with the client.
Sr. Security Developer
Confidential, Falls Church, VA
Responsibilities:
- Worked in Perl, C, Java, and Python to code hundreds of vulnerability scanning methods for IBM DB2, Websphere, Oracle DB, Weblogic, and Apache.
- Developed CloudStack and Joomla plugins for database integrated Citrix XenServer, and Chargify API.
- Provided risk management training sessions with DISA and DHA to formally deliver software and promote the system security planning and remediation cycle.
- Assisted DARPA in quality management research utilizing memory pinning in embedded systems.
Sr. Security Manager
Confidential, Reston, VA
Responsibilities:
- Implemented Qualys vulnerability scanning and integrated Trustwave SIEM integration. Designed a FIPS 140-2 compliant, fully meshed Juniper SSG IPSEC overlay spanning two data centers and 25 offices including Cisco routers Nexxus/Catalyst switches Nokia Checkpoint firewalls. Negotiated Interconnection agreements with the Small Business Administration.
- Worked with Wireshark protocol analyzers to resolve problems with tcp/ip mainframe gateway connectivity involving Juniper IPSec, IP WAN routing, Clustered Checkpoint firewalls, and Unisys Web Transaction Server for ClearPath OS Comm Trace.
- Planned under OMB Memorandum M-08-05 for the establishment of DHS NCSD compliant Redundant Trusted Internet Connections, disaster recovery functions, FIPS 140-2 compliance, and Interconnection Agreements.
- Managed data center contractor to consolidate infrastructure and support 0AM&P of physical WAN (ASA firewalls, and F5 ASM, BIGIP, ACE Load Balancers, VPN, Checkpoint).
Network Manager
Confidential, Washington, DC
Responsibilities:
- Procured a $77M phase I budget from the US Dept of Education as a result of establishing the new program and working with the change control board. The 3 phased endeavor was driven by OMB requirement for operational deployment and use of Internet Protocol version 6 and to “ Enable ubiquitous security services for end-to-end network communications that will serve as the foundation for securing future Federal IT systems” .
- Reviewed contract deliverables for the data center contractor and refined project requirements and SLAs for based on NIST SP 800-128 guidance on security focused configuration management.
- Audited network security policy and capabilities for level 2 compliance with FIPS 140-2 and firewall rule optimization assessments.
- Worked with telecommunications carriers to identify call center capacity issues from a PSTN point of view, establish appropriate capacity planning procedures and reports, and train the call center operator. Architected a new telecommunications solution, and defined compliance for capacity and disaster recovery controls.
Senior Network Engineer (NMS)
Confidential, Sterling, VA
Responsibilities:
- Co-designed and transitioned the world's first two IPv6 top-level global DNS domains using anycast as a dDoS remediation strategy. The network was Awarded a blue ribbon from Telcordia in an ICANN RFP against Verisign for management of dot net domains.
- Worked with IETF and Cisco Systems to participate in IOS Beta testing of carrier sensitive call signalling. Utilized DNS for e.164 off net calling. This testing lead to Cisco's development of the multi-protocol VoIP gateway (Cisco Routers and switches).
- Developed and integrated J2EE applications and databases, SNMP management systems, and ISO procedures into NOC to support every major PSTN carrier in North America and the global DNS. Evaluated and implementated monitoring and reporting with Infovista, Netcool modules, HP Openview, and CA eHealth.
- Provided advanced critical support and mentoring to the NOC while developing and establishing procedures for external customers including application integrated global telecommunications carriers.
- Developed and implemented software to measure the performance of business services using Java,Perl,SQL and numerous APIs including Arbor, Netcool, OpenView, and SNMP.
- Implemented global GPRS/GGSN signaling and provisioning platforms throughout europe upon the GSMA GRX cont ract award. Implemented Tekelec gateways on Linux using ss7 A links over euro E1 for GSM MAP application and inter-carrier call routing. Tested and implemented Cisco GGSN integration with IETF protocols for IP/GPRS routing of instant messages.
- Worked with ARIN and RIPE to identify unique global routing needs as required for inter-site and inter-carrier global communication privately and over the Internet.
- Completed feasibility and planning with vendors for the integration of dark fiber SDH services with data centers, Internet exchanges and legacy TDM network services.
- Lead and participated in hands on efforts to implement service Confidential over 50 global points of presence including network and security infrastructure, F5 and cisco load balancers, Unix systems, mass storage, and firewalls.
Owner/Managing Engineer
Confidential, Herndon, VA
Responsibilities:
- Hired, managed, and mentored engineers to support ongoing development and operations of Unix systems and Cisco networks upon procuring a federal contract with the US Dept. of HHS.
- Managed all operations within an annual budget and payroll which grew to one-million annually.
- Successfully managed to sale of the company for a pre-IPO opportunity with the FCC and Lockheed Martin.
Voice and Video Systems Engineer
Confidential, New York, NY
Responsibilities:
- Evaluated class 5 SS7 soft switch technologies for carrier VoIP solutions from various manufacturers. Characterized interoperability, advanced functionality, and global scalability using IETF and ITU models.
- Developed and executed test plans based upon the NANP, ETSI, and ANSI standards.
Internetworking Expert
Confidential, Columbia, MD
Responsibilities:
- Provided design, testing, and implementation services following the acquisition of InternetMCI.
- Developed Netcool Omnibus Rules to monitor the quality of call processing and authorization.
- Planned, developed, and implemented the next generation (N3) SS7 offload architecture to support 5 million subscribers in 23 US cities.
Consultant/Network Planner
Confidential, Reston, VA
Responsibilities:
- Worked with the Packet Engineering team to develop software in Procomm Aspect to streamline and automate network planning procedures.
- Quantified raw ISDN network performance data, analyzed circuit and call rotary configurations, and automated service orders on the Sprint mainframe system.
Communications Engineer III
Confidential, Seabrook, MD
Responsibilities:
- Installed Marconi (Fore) ATM switches and Cisco routers to provide inter-agency multimedia communications and Internet services.
- Maintained and upgraded Sun Solaris and SGI servers, mass storage systems and web software.
- Developed, tested and implemented LDAP based SMTP system.
- Implemented Tripwire and SATAN security monitoring tools and revision control systems.
Unix Administrator
Confidential, Temple Hills, MD
Responsibilities:
- Trained and hired personnel to establish a NOC (7 technical staff) supporting 1300 network customers and over 5000 network nodes.
- Developed and implemented a completely home grown SNMP/RDMS system and NOC Tools.
- Provided advanced technical support and trained implementation engineers to work issues including FIREWALL, SMTP, LAN, CPE. and WAN communications.
- Installed over 30 IP firewalls for WAN customers within the U.S. Armed Services, and intelligence agencies of the U.S. federal government.
Consultant/Contractor
Confidential, Brookfield, WI
Responsibilities:
- Worked with end users to resolve issues concerning Oracle / IP Integrated MVS systems.
- Developed and maintained HLLAPI, perl, awk, SQL, and JCL scripts.
Staff Assistant
Confidential, Washington, DC
Responsibilities:
- Developed distributed confidential dBase application integration.
- Maintained and ehhanced a 200 node Novell IPX LAN with TCP/IP and SNA access.
Intern
Confidential, Washington, DC
Responsibilities:
- Worked on the staff of confidential, IV and provided database and LAN application support.
- Supported confidential LAN.
